PT-2023-2451 · Openssl+8 · Openssl+8

Dmitry Belyavsky

+2

·

Published

2023-01-13

·

Updated

2024-06-15

·

CVE-2023-0401

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. This occurs when the hash algorithm used for the signature is known to the OpenSSL library, but the implementation of the hash algorithm is not available, causing the digest initialization to fail. The unavailability of an algorithm can be caused by using FIPS enabled configuration of providers or more commonly by not loading the legacy provider. PKCS7 data is processed by the SMIME library calls and also by the time stamp (TS) library calls. The TLS implementation in OpenSSL does not call these functions; however, third-party applications would be affected if they call these functions to verify signatures on untrusted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:0946
BDU:2023-02238
CVE-2023-0401
GHSA-VRH7-X64V-7VXQ
MGASA-2023-0130
OESA-2023-1135
OPENSUSE-SU-2023_0312-1
OPENSUSE-SU-2024:12716-1
RHSA-2023:0946
RHSA-2023:1199
RHSA-2023_0946
RLSA-2023:0946
RUSTSEC-2023-0013
SUSE-SU-2023:0312-1
USN-5844-1
USN-6564-1

Affected Products

Almalinux
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu